linkedin-content
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references and downloads installation scripts and supplementary tools from the vendor's official infrastructure and GitHub repositories.
- [COMMAND_EXECUTION]: Utilizes a custom command-line interface tool to execute various sub-applications for research and media generation, including performing web searches and interacting with external social media APIs.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external, untrusted sources which could contain malicious instructions.
- Ingestion points: The workflow encourages fetching trending content patterns from the open web using a search assistant tool in
SKILL.md. - Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are present in the provided examples when processing search results.
- Capability inventory: The skill has access to network operations and external platform posting capabilities through the
beltCLI utility. - Sanitization: There is no evidence of sanitization, validation, or filtering applied to the external data before it is incorporated into the content generation process.
Audit Metadata